Great Circle Associates Firewalls
(January 1997)
 

Indexed By Date: [Previous] [Next] Indexed By Thread: [Previous] [Next]

Subject: Re: Read-only Web Site (was AF hack)
From: cwg @ DeepEddy . Com
Date: Thu, 02 Jan 1997 17:46:52 -0600
To: mcnabb @ argus . cu-online . com (Paul McNabb)
Cc: Firewalls @ GreatCircle . COM
Cc: cwg @ DeepEddy . Com
In-reply-to: Your message of "Thu, 02 Jan 1997 12:41:29 CST." <199701021841 . MAA21415 @ argus . cu-online . com>

> The web server has two network connections, but has IP forwarding
> disabled.  Processes coming in from one network see all file systems
> as read-only (making /tmp RO is an option), and there is no mechanism
> for bypassing that, even if the process is root.  All device special
> files are complete inaccessible to all processes and all users -- also
> mknod(2) is disabled.  If a user comes in from the other network, 
> he/she can access the system normally, except that UID 0 (root) is
> treated as a normal account in terms of OS privilege, so attacks from
> this direction are also more tightly controlled (special programs
> are provided to manage the system instead of using a special account
> such as root).
> 
>                          +------------+
>          <-------------->| Secured    |<-------------->
>         internal network | Web Site   | Internet/PublicNet
>        (RW file systems) +------------+ (RO file systems)
> 
> When a Solaris host (x86 or SPARC) has been updated with this level
> of security, you can still use the r* commands, telnet, ftp, and
> even NFS from either side.  You can have the RO restriction be done
> on a per-file basis as well, so you can be creative about your setup.

How do you do this?

Chris

-- 
Chris Garrigues                    O-              cwg @
 DeepEddy .
 Com
  Deep Eddy Internet Consulting                     +1 512 432 4046
  609 Deep Eddy Avenue
  Austin, TX  78703-4513              http://www.DeepEddy.Com/~cwg/


Attachment: pgpTPhfXPpl6l.pgp
Description: PGP signature


References:
Indexed By Date Previous: Re: Lightweight Directory Access Protocol
From: "Mike 'Will tame Cisco's for food' Malik" <Mike . Malik @ ssds . com>
Next: RE: Air Force Web Site Hacked
From: Sebastian Stache <zeb @ sbbs . se>
Indexed By Thread Previous: Read-only Web Site (was AF hack)
From: mcnabb @ argus . cu-online . com (Paul McNabb)
Next: RE: Read-only Web Site (was AF hack)
From: "Stout, Bill" <bill . stout @ hidata . com>

Google
 
Search Internet Search www.greatcircle.com